Woody Leonhard’s no-bull news, tips and help for Windows and Office
RSS icon Email icon Home icon
  • Where are we with the patches?

    Posted on April 30th, 2009 at 14:36 woody 7 comments

    Reader BH writes:

    Before the current MS update release on Tuesday you were at Defcon 4
    and stated to install the patches. Did that statement include:

    Microsoft.NET Framework 3.5 Service Pack 1 and .NET Framework 3.5 Family Update (KB951847)

    KB952004

    KB956572

    KB959426

    KB960803

    Update Rollup for Actice X Killbit for Windows Vista (KB960715)

    I have been sitting on these for awhile and wish to know what to do with them.

    Your post regarding loading the patches did not specify the above and all along you have been stating not to load the Net Framework and Active X Killbit updates for some time now.

    I follow your MS-DEFCON and only load when you say so and I would guess many others follow the same procedure. Wish you would incorporate a chart with each to the updates listed and what to do with them. It would only involve the lastest listing plus those from past months  that you do not wish us to update.

    Wish I had time to do that! But it would be a monstrous task.

    Here’s what I recommend:

    I’m still ambivalent about KB951847. It breaks a lot of stuff. The ActiveX Killbit rollup also breaks a lot of stuff. I talk about both here.

    KB952004 and KB956572 are MS09-012. You should’ve installed that already, but if you haven’t, wait.

    KB959426 is MS09-015. Same comment.

    KB960803 is MS09-013, part of the massive Internet Explorer patch. Same comment, especially if you use Firefox.

    In general, if you follow the MS-DEFCON level, you’ll apply patches when they’re safe, and avoid applying patches when they aren’t. There are always a few stinkers – the ActiveX Killbit and .NET Framework patches fall into that category – but by and large you can apply the patches, when they’re fully baked, en masse.

    For now, hold off.

     

    7 responses to “Where are we with the patches?”

    1. Hans-Peter Guttmann

      Question, please: Woodie, do you know yet if the Update Rollup for ActiveX Kill Bits (KB960715) is incorporated in Service Pack 2 for Vista? Will running SP2 for Vista thus have the same effect as applying 960715?

      I still would hate to sacrifice Enveloper in WOPR 2003 for Vista SP2 . . .

      Thanks infinitely for sharing your knowledge!

    2. Woody
      You state”KB960803 is MS09-013, part of the massive Internet Explorer patch. Same comment, especially if you use Firefox.”

      Do you really mean KB963027 as the IE & & Cum. Update for IE7.

      Thanks

    3. Do I have to go to Internet Explorer 8? It’s asking, along with the patches. I use Firefox.

    4. Sanda -

      See http://www.askwoody.com/2009/6-7-8/

    5. Thanks. I have IE7 patched, I think and use Firefox.

    6. I too am a great follower of your advice on Microsoft Security Updates/Patches and am wondering what the current status is as to “Where are we on the patches” since your last advise on April 30, 2009? Would appreciate your recommendations as you have always been a life safer from the MS potential headaches.

    7. At this point, I suggest that you hold off on applying any outstanding patches. I intend to look at the general state of affairs this weekend. Right now, there’s nothing pressing.

    Leave a reply